
Lab
Lab
RouterOS vulnerabilities tested in my lab: what happens, who is exposed, and how to defend yourself. For 30 days, only for dojo students.
Image generated locally with ComfyUI from randomly selected elements. How the images are created

Lab · CVE-2018-14847
CVE-2018-14847: Recovering plaintext passwords from user.dat on RouterOS v6
We reproduced the CVE-2018-14847 vulnerability on RouterOS v6, confirming that an unauthenticated attacker can read the user.dat file and recover plaintext passwords due to a weak XOR transformation. The issue is fixed in versions 6.40.8, 6.42.11, and 6.49.7, where access to the file is denied.